Friday, November 4, 2016

StartCom is probably going away

StartCom is a root certification authority (CA) that has historically provided free SSL certificates. I've used them for a couple of my domains, and I've been very happy with the experience.

A while ago, though, it was discovered that StartCom's new owner WoSign had engaged in some sketchy behavior (intentionally backdating certificates). They also had severe bugs that allowed people to get valid certificates for domain's they don't own, which is a Very Bad ThingTM. Google Chrome has started phasing out its trust of those two CA's. I believe Firefox is also doing something similar.

This is basically a death sentence for that company, as it was for DigiNotar.

No comments:

Post a Comment